doodlelist Privacy Policy
Effective date: 2026-08-13
doodlelist processes the minimum personal information needed to provide dream journaling and AI image generation services. This policy explains the purposes of processing, retention periods, and user rights.
1. Personal Information We Process
- Account information: userId, login provider, provider identifier, email address, display name, profile image URL, and information needed to verify Firebase Auth ID tokens
- Authentication information: access tokens, refresh tokens, and refresh token expiration and revocation information. The app may store tokens in secure storage on the device to maintain sessions.
- Generation feature information: dream or journal text entered by the user, stylePreset, generation job status, result image URL, request/start/completion times, and error messages
- Generation history information: generation history retrieved from the server and some history data stored per user inside the app
- Report information: generationId, report reason, optional details, and review status
- Notification information: app-generated deviceId, FCM token, pushEnabled, platform, app version, build number, and change time
- App operation information: platform, appVersion, buildNumber, locale, IP address, User-Agent, request logs, error logs, and security event logs
- Legal consent information: Privacy Policy version, Terms version, marketing consent status, consent time, deviceId, IP address, and User-Agent
- Support information: support inquiry details, identity verification, and processing results
2. Purposes of Processing
- Identifying members, supporting guest/Google/Apple login, maintaining sessions with refresh tokens, account recovery, and customer support
- Generating images from dream text, checking generation status, providing generation history, and displaying or sharing result images
- Receiving, reviewing, blocking, or deleting generated results that may be inappropriate or infringe rights
- Sending notices, service operation messages, and push notifications allowed by the user
- Maintaining service security, analyzing failures, preventing misuse, complying with laws, and responding to disputes
- Managing consent records for the Terms and Privacy Policy, and deleting account and server data when an account is closed
3. Generative AI Processing
Dream or journal text entered by users is processed to generate images. A generation request may include information needed to process the job, such as user identifiers, input text, stylePreset, and request time.
doodlelist does not use user input text or generated images to train general-purpose AI models without separate consent. We may analyze statistics, errors, and reports to improve quality and safety. If we intend to use information in a personally identifiable form for model training, we will provide prior notice and obtain any required consent.
Please do not enter sensitive information, other people's personal information, or confidential information into dream text.
4. Retention and Use Periods
- Account information and generation history: retained while the account remains active. When account closure is completed, dream records and generated image data stored on the server are deleted.
- Refresh tokens: retained within the scope needed to maintain sessions and destroyed upon logout, reissuance, account closure, or expiration.
- Notification device information: retained to provide notifications or manage settings, and deleted or updated upon account closure or token invalidation.
- Reports and operational logs: retained for the period needed for report handling, security, failure analysis, and dispute response.
- Legal consent records: may be retained as needed to prove consent and respond to disputes.
Information that must be retained under applicable law or is needed to respond to rights-related disputes may be separately stored within the necessary scope.
5. Third-Party Sharing and Processing Entrustment
doodlelist does not provide personal information to third parties except where there is a legal basis or user consent.
To provide the service, we may use cloud infrastructure, image storage and delivery, AI image generation processing, push notifications, social login verification, and customer support tools. If we entrust personal information processing to an external provider or transfer information overseas, we will disclose required details such as provider name, destination country, transferred items, purpose, retention period, and opt-out method through this policy or a separate notice.
- Cloud/storage/CDN: server operation and generated image storage and delivery
- AI image generation processing systems: processing dream text into image generation jobs
- Firebase Authentication: Google/Apple social login authentication and token verification chosen by the user
- Push infrastructure such as Firebase Cloud Messaging: sending push notifications to devices
- Customer support tools: receiving and responding to inquiries
6. Destruction Procedures and Methods
Personal information is deleted in a way that makes recovery difficult once the retention period expires or the processing purpose is achieved. Electronic files are deleted securely, and information requiring separate retention is stored separately with restricted access.
7. User Rights
Users may request access, correction, deletion, suspension of processing, or withdrawal of consent regarding their personal information. Requests can be made through app settings or customer support. doodlelist will verify identity and handle requests under applicable law.
When account closure is completed, account and server data are deleted automatically.
Customer support: ldj0635@gmail.com
8. Security Measures
doodlelist applies reasonable safeguards, including access control, authentication token protection, encryption in transit, log management, and error and security event monitoring.
9. Automatically Collected Tools
The app service does not use cookies for personalized advertising. If the web test screen is used, HttpOnly refresh token cookies may be used to maintain sessions.
10. Children's Personal Information
doodlelist does not knowingly collect personal information from children who require consent from a legal representative. Please contact customer support with any related inquiries.
11. Changes to This Policy
If this policy changes, we will provide notice of the effective date, reason for change, and key changes through in-service notices or the legal document API. Changes that materially affect user rights will be announced sufficiently in advance.
12. Privacy Contact
For privacy inquiries, rights requests, or complaints, please contact us at ldj0635@gmail.com.